Agent skill

Stata Audit

by SepineTam in SepineTam/mcp-for-stata

Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp.

AGPL-3.0Auto-check passedResearch & Science

Install Stata Audit

skills CLI
$ npx skills add SepineTam/mcp-for-stata --skill stata-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SepineTam/mcp-for-stata stata-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SepineTam/mcp-for-stata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/stata-toolbox/skills/stata-audit .claude/skills/stata-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stata-audit
GitHub stars
264
Token cost
~1.2k tokens
SKILL.md length
532 words
Files
8 (incl. scripts, assets)
Skills in repo
6
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp.

  • A user asks what tools ran
  • SKILL.md covers Choose the Narrowest Script, Review Rules, Script Usage and Reporting Boundaries
  • Runs Python scripts from its folder; calls python
  • Whether a security guard blocked anything

What it does

Stata Audit is an agent skill from SepineTam/mcp-for-stata. Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp. Use when a user asks what tools ran, whether a security guard blocked anything, how one run links across JSONL files, whether snapshots are intact, or wants an interactive audit dashboard.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and assets (for example `scripts/analyze_audit.py`, `scripts/audit_common.py` and `scripts/inspect_audit.py`).

It sits in Research & Science, covering Econometrics and empirical research. It works with Model Context Protocol. The repository describes itself as: Stata-MCP: A MCP server for integrating Stata into your agent loop with a safety-first design. The licence is AGPL-3.0.

When your agent uses it

  • A user asks what tools ran
  • Whether a security guard blocked anything
  • How one run links across JSONL files
  • Whether snapshots are intact

Example prompts

  • “/stata-audit”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit d339615. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Stata Audit loads about 1.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 532 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from SepineTam/mcp-for-stata at commit d339615, republished under its AGPL-3.0 licence (© SepineTam). 532 words, ~1,223 tokens.

Download SKILL.mdSave it as .claude/skills/stata-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
stata-audit
description
Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp. Use when a user asks what tools ran, whether a security guard blocked anything, how one run links across JSONL files, whether snapshots are intact, or wants an interactive audit dashboard.
metadata.version
0.1.0

Stata-MCP Audit

Read Stata-MCP evidence without changing the source JSONL ledgers or snapshot objects. Resolve every script and template relative to this skill directory, while resolving the default evidence root from the user's current working directory as <cwd>/.statamcp.

Choose the Narrowest Script

User needScriptResult
Check security blocks or warningsscripts/security_audit.pySecurity decisions, whether execution was prevented, risk types, and linkage state
Summarize project usagescripts/analyze_audit.pyNeutral counts, observed period, tool mix, outcomes, snapshots, and limitations
Inspect recent records or one runscripts/inspect_audit.pySource-preserving records joined by exact run_id
Check evidence integrityscripts/validate_audit.pyLifecycle, timestamp, security-link, and full SHA-256 snapshot checks
Open an interactive viewscripts/render_audit_html.pyStandalone English HTML dashboard with linked ledgers and a movable time window

Use the user's project directory as the command working directory. Example:

bash
python /absolute/path/to/stata-audit/scripts/validate_audit.py .statamcp

All scripts accept an optional artifact-root argument and default to ./.statamcp. The text output is suitable for a quick review; add --json when structured downstream analysis is useful.

Review Rules

  • Join lifecycle records with exact run_id, not filename or time proximity.
  • Treat event == "blocked" with executed == false as a prevented call. A normal blocked call is security evidence, not a script failure.
  • Follow security_event_ids to audit/security.jsonl and report missing or inconsistent links.
  • Verify snapshot bytes against the complete recorded SHA-256. The first eight characters are display-only.
  • Treat missing terminal events as investigation leads, not proof that a tool executed or failed.
  • Treat client name and version as self-reported metadata, not verified user or agent identity.
  • Keep full paths masked unless the user explicitly needs them. The reporting scripts support --show-paths for that case.
  • Never edit, sort, truncate, rotate, replay, or repair evidence in place.
Show full SKILL.md (258 more words)Show less

Script Usage

Security review:

bash
python scripts/security_audit.py .statamcp
python scripts/security_audit.py .statamcp --json

Project usage analysis:

bash
python scripts/analyze_audit.py .statamcp

Inspect the latest records or reconstruct one exact run:

bash
python scripts/inspect_audit.py .statamcp --limit 20
python scripts/inspect_audit.py .statamcp --run-id <exact-run-id> --json

Validate evidence:

bash
python scripts/validate_audit.py .statamcp

Exit code 0 means no integrity error was found. Exit code 1 means the evidence is missing, malformed, inconsistent, or failed a snapshot hash check. Warnings remain visible but do not alone fail validation.

Render the combined dashboard or one tool view:

bash
python scripts/render_audit_html.py .statamcp
python scripts/render_audit_html.py .statamcp --tool stata_do

The default output directory is:

text
<cwd>/.statamcp/reports/html/

Combined reports use YYYYMMDD-HHMM-audit.html. A filtered report uses the tool name, for example YYYYMMDD-HHMM-stata_do.html. The renderer locates assets/audit_dashboard.html from its own Python-file location, so it works regardless of the user's current directory.

The dashboard derives its global start and end from the minimum and maximum timestamps in the selected evidence. Its two Time position handles start at those exact boundaries and control the visible chart start and end. Ordinary text uses Times New Roman; tool names, run IDs, ledgers, hashes, and paths use a monospace code font. Times are displayed as YYYY-MM-DD HH-MM with the viewer's local time-zone name and UTC offset.

After rendering, report the exact generated path and ask whether the user wants to open it. Open it only after the user agrees. Use the platform's normal local file opener (open on macOS, xdg-open on Linux, or start on Windows).

Reporting Boundaries

State conclusions as measurements from recorded tool calls. Do not claim that the audit captures unrecorded thinking, manual Stata actions, authorship, or a continuous agent session. If evidence has parse errors, unsupported schema versions, unmatched lifecycle events, missing security links, or failed hashes, surface those limitations before summarizing behavior.

© SepineTam, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, assets) in plugins/stata-toolbox/skills/stata-audit of SepineTam/mcp-for-stata.

  • SKILL.md
  • assets/audit_dashboard.html
  • scripts/analyze_audit.py
  • scripts/audit_common.py
  • scripts/inspect_audit.py
  • scripts/render_audit_html.py
  • scripts/security_audit.py
  • scripts/validate_audit.py

Open the folder on GitHubat commit d339615

Compare with similar skills

Stata Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stata Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stata Audit this skillSepineTam/mcp-for-stata264—~1.2kAutomated safety check: PassAGPL-3.0
Fin Data Acquisitioncsmar432/finai-research109—~2kAutomated safety check: PassMIT
Fin Generate Ideacsmar432/finai-research109—~2.5kAutomated safety check: PassMIT
Fin Idea Discoverycsmar432/finai-research109—~2.7kAutomated safety check: PassMIT
Fin Novelty Checkcsmar432/finai-research109—~1.4kAutomated safety check: PassMIT
Stata Replicationpedrohcgs/claude-code-my-workflow1.7k—~2.1kAutomated safety check: NotesMIT

Similar skills

  • Fin Data Acquisition

    csmar432/finai-research

    根据REFINEDDESIGN.md中的变量定义,自动获取所需数据并生成可执行的回归分析脚本(Python/Stata)。

    109 GitHub stars~2k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Generate Idea

    csmar432/finai-research

    针对经济金融研究方向的创意生成与评估。生成8-12个可发表的研究idea,过滤后在数据可行的情况下进行小规模实证验证,输出排序后的研究想法报告。

    109 GitHub stars~2.5k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Idea Discovery

    csmar432/finai-research

    经济金融研究的完整想法发现流程。从研究方向出发,经过文献综述、想法生成、新颖性验证、实证方法设计和数据获取,输出经过数据实证验证的可执行研究方案。

    109 GitHub stars~2.7k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Novelty Check

    csmar432/finai-research

    验证经济金融研究想法的新颖性。在JF、JFE、RFS、JME等顶刊及arXiv中搜索近三年文献,输出结构化新颖性报告和定位策略。

    109 GitHub stars~1.4k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Stata Replication

    pedrohcgs/claude-code-my-workflow

    End-to-end Stata replication pipeline — scaffolds numbered .do files in scripts/stata/, executes them via the stata-mcp MCP server, captures logs and outputs to output/, and produces…

    1.7k GitHub stars~2.1k tokensUpdated 13 days ago
    Research & ScienceAuto-check: notes
  • Aer Statspai

    brycewang-stanford/Auto-Empirical-Research-Skills

    A skill your agent uses when aer-identification has fixed the design, after methodology choice and before aer-robustness or aer-tables-figures, to run an AER-track analysis with StatsPAI — the…

    4.6k GitHub stars~3k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed

More from SepineTam/mcp-for-stata

  • Diagnostic Dofile

    SepineTam/mcp-for-stata

    A skill your agent uses when the user needs to inspect, audit, or diagnose the safety of a Stata do-file.

    264 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • MCP Smoke Test

    SepineTam/mcp-for-stata

    Run a local smoke test for the Stata-MCP server. An agent skill from SepineTam/mcp-for-stata.

    264 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed
  • Stata Discover

    SepineTam/mcp-for-stata

    A skill your agent uses when you need to find Stata on the user's machine or configure stata-mcp to use it.

    264 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Rfc Impl Generator

    SepineTam/mcp-for-stata

    Generate RFC and IMPL documents from a user-provided feature/fix description.

    264 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Stata Skill

    SepineTam/mcp-for-stata

    A packaged Stata Runner skill via official MCP-for-Stata server including statado, adopackageinstall, help, readlog and getdatainfo tools.

    264 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed

Questions about Stata Audit

What does Stata Audit do?

Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp. Stata Audit is an agent skill from SepineTam/mcp-for-stata.statamcp.

When should I use Stata Audit?

Stata Audit fits situations like: A user asks what tools ran; whether a security guard blocked anything; how one run links across JSONL files; whether snapshots are intact.

How do I install Stata Audit in Claude Code?

Run `npx skills add SepineTam/mcp-for-stata --skill stata-audit -a claude-code`. Or copy the skill folder (plugins/stata-toolbox/skills/stata-audit in SepineTam/mcp-for-stata) into .claude/skills/stata-audit in your project. Claude Code loads it when a task matches its description.

How do I install Stata Audit in Codex?

Run `npx skills add SepineTam/mcp-for-stata --skill stata-audit -a codex`. Or copy the skill folder (plugins/stata-toolbox/skills/stata-audit in SepineTam/mcp-for-stata) into .agents/skills/stata-audit in your project. Codex loads it when a task matches its description.

Can I use Stata Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SepineTam/mcp-for-stata --skill stata-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stata-audit, .gemini/skills/stata-audit, .github/skills/stata-audit and .opencode/skills/stata-audit in your project.

What does Stata Audit need to run?

Going by SKILL.md and its folder, Stata Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Stata Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Stata Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Stata Audit use?

Stata Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stata Audit use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stata Audit?

Skills that share tags, products or a category with Stata Audit: Fin Data Acquisition (csmar432/finai-research, 109 stars), Fin Generate Idea (csmar432/finai-research, 109 stars), Fin Idea Discovery (csmar432/finai-research, 109 stars) and Fin Novelty Check (csmar432/finai-research, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stata Audit?

SepineTam (a GitHub user) maintains it in SepineTam/mcp-for-stata, which has 264 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 6, 2026.

Source: SepineTam/mcp-for-stata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.